KEV Additions, Gitea RCE, Cisco FMC Zero-Day Lead Daily Brief
CISA adds six exploited vulnerabilities to KEV; Gitea RCE exploited; Cisco FMC zero-day patched; Ubiquiti UniFi flaws disclosed.

CISA has added six vulnerabilities to its Known Exploited Vulnerabilities catalog, including critical flaws in Citrix NetScaler ADC and Gateway (CVE-2026-8452), Microsoft SQL Server (CVE-2019-1068), and the Linux kernel (CVE-2022-0995). The NetScaler vulnerability, a memory overflow, can lead to denial of service when the appliance is configured as a gateway. Microsoft SQL Server's RCE vulnerability stems from improper handling of internal functions, while the Linux kernel flaw involves an out-of-bounds memory write in the watch_queue subsystem, potentially allowing local privilege escalation. These additions highlight ongoing threats to widely used infrastructure components.
Gitea, a self-hosted Git service, faces a critical RCE vulnerability (CVE-2026-60004) in versions prior to 1.27.1. The flaw exists in the diffpatch API and can be exploited through Git hook installation, allowing remote code execution. This vulnerability has reportedly been actively exploited in the wild, with attackers deploying miner-like payloads. As reported by The Hacker News, the exploit chain involves Git hook installation via the diffpatch API.
Cisco is addressing a critical authentication bypass vulnerability (CVE-2026-20079) in its Secure Firewall Management Center (FMC) software. This flaw allows unauthenticated, remote attackers to execute script files and gain root access. The vulnerability has been exploited in the wild as a zero-day, with attackers leveraging static credentials to potentially access sensitive data. BleepingComputer notes that Cisco has released patches for this and other vulnerabilities affecting its SD-WAN and IOS XE products.
Ubiquiti's UniFi OS is affected by a series of critical vulnerabilities, including improper access control flaws (CVE-2026-77534, CVE-2026-77536) that allow privilege escalation, and an improper neutralization of CRLF sequences vulnerability (CVE-2026-77550) enabling authentication bypass. These flaws, some with CVSS scores of 10.0, pose significant risks to devices running UniFi OS, potentially allowing unauthorized access and control. Cyber Security News detailed 21 critical flaws impacting the UniFi line.
Several other critical vulnerabilities have been disclosed across various platforms. WordPress plugins are facing risks, including an unauthenticated PHP object injection in Geo Controller (CVE-2026-78286). Apache Tomcat's DIGEST authenticator has an authentication bypass vulnerability (CVE-2026-65905) due to a nonceCount issue. Additionally, vulnerabilities in Joomla extensions (CVE-2026-77998), Trendnet devices (CVE-2026-77946), and Drupal Commerce Elavon (CVE-2026-16641) present further security challenges.